CVE-2024-8515
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-8515 is a Stored Cross-Site Scripting (XSS) vulnerability affecting Themesflat Addons For Elementor plugin for WordPress. The flaw, present in several widgets such as 'TF E Slider Widget', 'TF Video Widget', and 'TF Team Widget', allows authenticated attackers with Contributor-level access or higher to inject malicious scripts. These scripts will be executed whenever a user visits an injected page, due to insufficient input sanitization and output escaping on URL attributes in all versions up to 2.2.1. This vulnerability poses a significant risk, as it enables attackers to manipulate web pages and potentially steal sensitive user data. It is strongly recommended that users update to the latest version of the plugin or completely remove it until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.